Skip to content

Conversation

@brijeshp56
Copy link
Collaborator

Tested Reusable trufflehog scan workflow for secrets with test repo https://github.com/marklogic/copyrighttest/pull/36

@brijeshp56 brijeshp56 self-assigned this Dec 18, 2025
Copilot AI review requested due to automatic review settings December 18, 2025 08:10
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds a reusable TruffleHog secret scanning workflow to detect secrets in pull request changes. The workflow is integrated into the PR workflow template and supports optional file/folder exclusions.

Key changes:

  • Added a new reusable workflow for TruffleHog secret scanning
  • Integrated the TruffleHog scan job into the PR workflow template
  • Implemented optional exclusion pattern support via .trufflehog-exclude file

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
templates/pr-workflow.yml Adds TruffleHog scan job to PR workflow template
.github/workflows/trufflehog-scan.yml Creates reusable workflow for secret scanning with TruffleHog

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

echo "args=${ARGS}" >> "$GITHUB_OUTPUT"
- name: Secret Scanning
uses: trufflesecurity/trufflehog@main
Copy link

Copilot AI Dec 18, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using '@main' for the TruffleHog action is not recommended for production workflows as it may introduce breaking changes without notice. Consider pinning to a specific version or commit SHA for stability and reproducibility.

Suggested change
uses: trufflesecurity/trufflehog@main
uses: trufflesecurity/trufflehog@v3

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants